Vulnerability Name: | CVE-2016-1341 (CCN-110912) | ||||||||||||
Assigned: | 2016-02-23 | ||||||||||||
Published: | 2016-02-23 | ||||||||||||
Updated: | 2016-12-06 | ||||||||||||
Summary: | Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-255 CWE-264 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1341 Source: CISCO Type: Vendor Advisory 20160223 Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability Source: SECTRACK Type: UNKNOWN 1035088 Source: XF Type: UNKNOWN cisco-nexus-cve20161341-default-account(110912) Source: CCN Type: Cisco Security Advisory cisco-sa-20160223-nx2000 Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |